A superuser account is any administrative account that grants full access to an operating system or application such as a database. On Linux and UNIX platforms, system accounts such as root or service accounts such as oracle are needed for installation, configuration, administration and management tasks. But as Gartner (Research Report ID# G00130427) has noted, Linux and UNIX systems inherently lack a scalable and simple model for administrative delegation. In many organizations Linux and UNIX personnel - such as system administrators, DBAs, backup operators and help desk staff - are routinely given increased privileges to accomplish even narrowly focused administrative tasks such as performing backups or managing a web site.
Organizations are becoming increasing aware of the risk that such broad administrative grants pose for potential theft of corporate IP, insider attacks, or even inadvertent changes that adversely affect systems or data. But alternatives such as sudo are frequently so complex to manage that some organizations simply live with the exposure because they have no practical way to limit privileges without hindering users in performing necessary administrative tasks.
The Centrify Suite provides a single, unified privilege management solution across more than 225 Linux and UNIX platforms. Instead of relying on complex scripting, proprietary databases, or expensive server architectures, Centrify joins your Linux and UNIX systems to your existing Active Directory infrastructure. You can then model Linux and UNIX user roles within Active Directory and apply those roles to the existing Active Directory identities. With the Centrify Suite you can:
The DirectControl MIIS Management Agent is a great example of how Centrify enables customers to get more value out of their investment in Active Directory and MIIS.
Michael Stephenson
Director
Windows Server Division
Microsoft Corp.